CVE-2023-31698: Bludit
Medium severity, CVSS 5.4. EPSS: 2.6% chance of exploitation in the next 30 days.
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
Affected products
- Bludit Bludit: version 3.14.1 only
Published 2023-05-17. Last modified 2026-06-17.